A vulnerability unknown to the vendor and public — attackers have a head start.
A zero-day is a vulnerability that is exploited (or exploitable) before the vendor knows it exists — the vendor has had "zero days" to fix it. They are the most dangerous class of flaw because no patch, advisory, or signature exists yet.
Safeguard Research discovers zero-days in open-source packages through automated analysis and publishes them as SGZ advisories (SGZ-YYYY-XXXXX) with severity, affected versions, and remediation guidance — often before a public CVE exists. Every SGZ advisory wears the gold ◆ SGZ ZERO-DAY badge across this site.